{
"stig": {
"date": "2020-01-23",
"description": "None",
"findings": {
"V-6900": {
"checkid": "C-20294r1_chk",
"checktext": "a)\tReview site documentation to validate that procedures are in place to protect the FEP service subsystem and diskette drive:\n\n-\tDocuments and procedures restricting access to the hardware components of the FEPs.\n\nb)\tIf the hardware components of the FEPs are located in secure locations, there is NO FINDING.\n\nc)\tIf the hardware components of the FEPs are not located in secure locations, this is a FINDING.",
"description": "If components of the FEPs are not properly protected they can be stolen, damaged, or disturbed. Without adequate physical security, unauthorized users can access the control panel, the operator console, and the diskette drive of the service subsystem. Therefore, they can interfere with the normal operations of the FEPs. Improper control of FEP components could compromise network operations.",
"fixid": "F-18249r1_fix",
"fixtext": "Ensure that hardware components of the FEPs are protected as specified below:\n\nPhysical security is the first level of security control for the FEPs. Install all hardware components of the FEPs in secure locations where they cannot be stolen, damaged, or disturbed. Make sure that FEP hardware is located in a secure area with limited access to authorized personnel. ",
"iacontrols": null,
"id": "V-6900",
"ruleID": "SV-7195r3_rule",
"severity": "medium",
"title": "All hardware components of the FEPs are not placed in secure locations where they cannot be stolen, damaged, or disturbed",
"version": "ZFEP0011"
},
"V-6901": {
"checkid": "C-3279r1_chk",
"checktext": "a)\tReview site documentation to validate that procedures are in place to protect the FEP service subsystem and diskette drive:\n\n-\tDocuments and procedures restricting access to the functions of the service subsystem from the control panel.\n-\tDocuments and procedures restricting access to the functions of the service subsystem from the local and/or remote operator consoles (e.g., physical access, password control, key-lock switch of modems, etc.).\n-\tDocuments and procedures restricting access to the diskette drive of the service subsystem.\n\nb)\tIf a procedure is in place to restrict access to the functions of the service subsystem, there is NO FINDING.\n\nc)\tIf a procedure is in place to restrict access to the functions of the service subsystem from operator consoles (local and/or remote), there is NO FINDING.\n\nd)\tIf a procedure is in place to restrict access to the diskette drive of the service subsystem, there is NO FINDING.\n\ne)\tIf no procedure exists for any of the above functions of the service subsystem and FEP resources, this is a FINDING.",
"description": "If components of the FEPs are not properly protected they can be stolen, damaged, or disturbed. Without adequate physical security, unauthorized users can access the control panel, the operator console, and the diskette drive of the service subsystem. Therefore, they can interfere with the normal operations of the FEPs. Improper control of FEP components could compromise network operations.",
"fixid": "F-18250r1_fix",
"fixtext": "Ensure that all hardware components of the FEPs are protected as decribed below and supporting documentation procedures exist for each item:\n\n1. Documents and procedures restricting access to the hardware components of the FEPs.\n\n2. Documents and procedures restricting access to the functions of the service subsystem from the control panel.\n\n3. Documents and procedures restricting access to the functions of the service subsystem from the local and/or remote operator consoles (e.g., physical access, password control, key-lock switch of modems, etc.).\n\n4. Documents and procedures restricting access to the diskette drive of the service subsystem.\n",
"iacontrols": null,
"id": "V-6901",
"ruleID": "SV-7196r3_rule",
"severity": "medium",
"title": "Procedures are not in place to restrict access to FEP functions of the service subsystem from operator consoles (local and/or remote), and to restrict access to the diskette drive of the service subsystem.",
"version": "ZFEP0012"
},
"V-6902": {
"checkid": "C-20295r1_chk",
"checktext": "a)\tReview site documentation to validate that procedures are in place to protect the FEP service subsystem and diskette drive:\n\n-\tDocuments and procedures regarding the NCP load and dump processes.\n\nb)\tIf a procedure is in place relative to the NCP load and dump processes, there is NO FINDING.\n\nc)\tIf no procedure is in place relative to the NCP load and dump processes, this is a FINDING.",
"description": "If components of the FEPs are not properly protected they can be stolen, damaged, or disturbed. Without adequate physical security, unauthorized users can access the control panel, the operator console, and the diskette drive of the service subsystem. Therefore, they can interfere with the normal operations of the FEPs. Improper control of FEP components could compromise network operations.",
"fixid": "F-18251r1_fix",
"fixtext": "If documented procedures for loading and dumping the FEP NCP (Network Control Program) are not available. Create a procedure document for dumping and loading the FEP and make sure that they are available to the IAO and to authorized personnel responsible to perform these functions.",
"iacontrols": null,
"id": "V-6902",
"ruleID": "SV-7197r3_rule",
"severity": "medium",
"title": "A documented procedure is not available instructing how to load and dump the FEP NCP (Network Control Program).",
"version": "ZFEP0013"
},
"V-6903": {
"checkid": "C-20296r1_chk",
"checktext": "a)\tReview site documentation to validate that procedures are in place to protect the FEP service subsystem and diskette drive:\n\n-\tAll documents and procedures that apply to FEP operations including network management, FEP initialization, IPL, shutdown, NCP dumping, backup, and recovery.\n\nb)\tIf a log is in place to keep track of all hardware upgrades and software changes, there is NO FINDING.\n\nc)\tIf no log is in place to keep track of all hardware upgrades and software changes, this is a FINDING.",
"description": "If components of the FEPs are not properly protected they can be stolen, damaged, or disturbed. Without adequate physical security, unauthorized users can access the control panel, the operator console, and the diskette drive of the service subsystem. Therefore, they can interfere with the normal operations of the FEPs. Improper control of FEP components could compromise network operations.",
"fixid": "F-18252r1_fix",
"fixtext": "The systems programmer will see that a a log of all hardware and software upgrades/changes has been created for auditing purposes and problem tracking. All changes and upgrades will be logged.",
"iacontrols": null,
"id": "V-6903",
"ruleID": "SV-7198r3_rule",
"severity": "medium",
"title": "An active log is not available to keep track of all hardware upgrades and software changes made to the FEP (Front End Processor).",
"version": "ZFEP0014"
},
"V-6904": {
"checkid": "C-20297r1_chk",
"checktext": "a)\tRefer to the following report produced by the Data Set and Resource Data Collection:\n\n-\tSENSITVE.RPT(NCPRPT)\n\n___\tThe ACP data set rules for NCP data sets allow inappropriate access.\n\n___\tThe ACP data set rules for NCP data sets does not restrict UPDATE and/or ALL access to authorized personnel (e.g., systems programming personnel).\n\nb)\tIf both of the above are untrue, there is NO FINDING.\n\nc)\tIf either of the above is true, this is a FINDING.",
"description": "If components of the FEPs are not properly protected they can be stolen, damaged, or disturbed. Without adequate physical security, unauthorized users can access the control panel, the operator console, and the diskette drive of the service subsystem. Therefore, they can interfere with the normal operations of the FEPs. Improper control of FEP components could compromise network operations.",
"fixid": "F-18253r1_fix",
"fixtext": "Identify Names of the following data sets used for installation and in development/production environments:\n\t\n-\tNCP system data sets\n-\tNCP source definition data sets\n-\tNCP load modules\n-\tNCP host dump data sets\n-\tNCP utility programs\nHave the IAO validate that they are properly protected by the ACP. And that only authorized personnel are permitted UPDATE and/or ALLOCATE access (e.g., z/OS systems programming personnel).",
"iacontrols": null,
"id": "V-6904",
"ruleID": "SV-7199r3_rule",
"severity": "medium",
"title": "NCP (Net Work Control Program) Data set access authorization does not restricts UPDATE and/or ALLOCATE access to appropriate personnel.",
"version": "ZFEP0015"
},
"V-6905": {
"checkid": "C-20301r1_chk",
"checktext": "a)\tReview site documentation to validate that procedures are in place to protect the FEP service subsystem and diskette drive:\n\n-\tDocuments and procedures restricting access to the functions of the service subsystem from the local and/or remote operator consoles (e.g., physical access, password control, key-lock switch of modems, etc.).\n\nb)\tIf a password control is in place to restrict access to the service subsystem via the operator consoles (local and/or remote), there is NO FINDING.\n\nc)\tIf a key-lock switch is used to protect the modem supporting the remote console of the service subsystem, there is NO FINDING.\n\nd)\tIf no procedure exists for any of the above functions of the service subsystem and FEP resources, this is a FINDING.",
"description": "If components of the FEPs are not properly protected they can be stolen, damaged, or disturbed. Without adequate physical security, unauthorized users can access the control panel, the operator console, and the diskette drive of the service subsystem. Therefore, they can interfere with the normal operations of the FEPs. Improper control of FEP components could compromise network operations.",
"fixid": "F-18256r1_fix",
"fixtext": "If any of the below procedures are not in place, than correct the situation by documenting the missing procedure(s).\n\nThe systems programmer should validate that Control authorization to use service subsystem console (local or remote) by FEP internal security control through password validation. Restrict access to these passwords to the absolutely minimum number of necessary personnel. Use of vendor default passwords is prohibited. Assign different passwords for the local and remote consoles. Disconnect the local/remote console after three unsuccessful attempts to log on. Passwords used by vendor (COMTEN, IBM, CNT, or AMDAHL) service personnel will be changed after any maintenance is done. All passwords will be changed every 90 days. Restrict permission to change passwords only to authorized personnel.\n\nUse a key lock switch on the modem supporting the remote console of the service subsystem to prevent unauthorized access. The key lock switch is only open for scheduled and authorized remote access.",
"iacontrols": null,
"id": "V-6905",
"ruleID": "SV-7200r3_rule",
"severity": "medium",
"title": "A password control is not in place to restrict access to the service subsystem via the operator consoles (local and/or remote) and a key-lock switch is not used to protect the modem supporting the remote console of the service subsystem.",
"version": "ZFEP0016"
}
},
"profiles": {
"MAC-1_Classified": {
"description": "",
"findings": {
"V-6900": "true",
"V-6901": "true",
"V-6902": "true",
"V-6903": "true",
"V-6904": "true",
"V-6905": "true"
},
"id": "MAC-1_Classified",
"title": "I - Mission Critical Classified"
},
"MAC-1_Public": {
"description": "",
"findings": {
"V-6900": "true",
"V-6901": "true",
"V-6902": "true",
"V-6903": "true",
"V-6904": "true",
"V-6905": "true"
},
"id": "MAC-1_Public",
"title": "I - Mission Critical Public"
},
"MAC-1_Sensitive": {
"description": "",
"findings": {
"V-6900": "true",
"V-6901": "true",
"V-6902": "true",
"V-6903": "true",
"V-6904": "true",
"V-6905": "true"
},
"id": "MAC-1_Sensitive",
"title": "I - Mission Critical Sensitive"
},
"MAC-2_Classified": {
"description": "",
"findings": {
"V-6900": "true",
"V-6901": "true",
"V-6902": "true",
"V-6903": "true",
"V-6904": "true",
"V-6905": "true"
},
"id": "MAC-2_Classified",
"title": "II - Mission Support Classified"
},
"MAC-2_Public": {
"description": "",
"findings": {
"V-6900": "true",
"V-6901": "true",
"V-6902": "true",
"V-6903": "true",
"V-6904": "true",
"V-6905": "true"
},
"id": "MAC-2_Public",
"title": "II - Mission Support Public"
},
"MAC-2_Sensitive": {
"description": "",
"findings": {
"V-6900": "true",
"V-6901": "true",
"V-6902": "true",
"V-6903": "true",
"V-6904": "true",
"V-6905": "true"
},
"id": "MAC-2_Sensitive",
"title": "II - Mission Support Sensitive"
},
"MAC-3_Classified": {
"description": "",
"findings": {
"V-6900": "true",
"V-6901": "true",
"V-6902": "true",
"V-6903": "true",
"V-6904": "true",
"V-6905": "true"
},
"id": "MAC-3_Classified",
"title": "III - Administrative Classified"
},
"MAC-3_Public": {
"description": "",
"findings": {
"V-6900": "true",
"V-6901": "true",
"V-6902": "true",
"V-6903": "true",
"V-6904": "true",
"V-6905": "true"
},
"id": "MAC-3_Public",
"title": "III - Administrative Public"
},
"MAC-3_Sensitive": {
"description": "",
"findings": {
"V-6900": "true",
"V-6901": "true",
"V-6902": "true",
"V-6903": "true",
"V-6904": "true",
"V-6905": "true"
},
"id": "MAC-3_Sensitive",
"title": "III - Administrative Sensitive"
}
},
"slug": "zos_fepacf2",
"title": "zOS FEP for ACF2 STIG",
"version": "None"
}
}